CVE-2026-58502
Last modified
CVE-2026-58502 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. An issue title containing shell command-substitution syntax can therefore execute commands on the GitHub Actions runner before the title is included in the Discord notification sent through DISCORD_WEBHOOK. Successful exploitation can manipulate or spoof trusted bot notifications and may expose the Discord webhook secret or other workflow environment data, depending on repository permissions. This issue is fixed by commit 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| gouef | githubtoplanguages | < 6bf9c3a9cb66c937b9047ca266b3d02f2bb11027 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-58502?
How severe is CVE-2026-58502?
How do I fix CVE-2026-58502?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58493grav-plugin-database is the database plugin for Grav CMS. Pr…5.1
- CVE-2026-58494Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.…6.5
- CVE-2026-58499EverOS is a memory runtime for agents. Prior to 1.0.1, EverO…8.2
- CVE-2026-5850A vulnerability was identified in Totolink A7100RU 7.4cu.231…9.8
- CVE-2026-58500MCP Appium is an MCP server that provides AI assistants with…8.2
- CVE-2026-58501Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Setti…5.9
- CVE-2026-58503Frappe is a full-stack web application framework. Prior to 1…6.9
- CVE-2026-58504draw.io is a configurable diagramming and whiteboarding appl…6.1
- CVE-2026-58507Private Repository Existence Disclosure via go-get Meta Endp…5.3
- CVE-2026-58508Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebi…9.1
- CVE-2026-5851A security flaw has been discovered in Totolink A7100RU 7.4c…9.8
- CVE-2026-58510GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API …4.3
Are you affected by CVE-2026-58502?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
